Best Incident Response Software for Small Business

How Many Incident Response Software Products Does G2 Track?

Total Products under this Category: 109

Category Stats (Sep 2026)

  • Average Rating: 4.48/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: ReliaQuest GreyMatter (+2.12%) - Among all products in this category, ReliaQuest GreyMatter recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Incident Response Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 5,600+ Authentic Reviews
  • 109+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Incident Response Software

G2 Grid® for Incident Response Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Tines Stories, Torq AI SOC Platform, Palo Alto Cortex XSIAM, KnowBe4 PhishER/PhishER Plus, Cynet, SentinelOne Singularity Endpoint, and Wazuh.

Underlying data: [Grid® JSON](https://www.g2.com/categories/incident-response/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=tines-stories&focus%5B%5D=torq-ai-soc-platform&focus%5B%5D=palo-alto-cortex-xsiam&focus%5B%5D=knowbe4-phisher-phisher-plus&focus%5B%5D=cynet&focus%5B%5D=sentinelone-singularity-endpoint&focus%5B%5D=wazuh&segment=small-business)

CrowdStrike Falcon Endpoint Protection Platform

Organizations today face a serious challenge: managing numerous security vendors and tools while confronting an ever-evolving threat landscape. Sophisticated adversaries are becoming smarter, faster, and more evasive, launching complex attacks that can strike in minutes or even seconds. Traditional security approaches struggle to keep pace, leaving businesses vulnerable. The CrowdStrike Falcon Platform addresses this by offering a unified, cloud-native solution. It consolidates previously siloed security solutions and incorporates third-party data into a single platform with one efficient and resource-conscious agent, leveraging advanced AI and real-time threat intelligence. This approach simplifies security operations, speeds analyst decision making, and enhances protection to stop the breach, allowing organizations to reduce risk with less complexity and lower costs. CrowdStrike's Falcon Platform includes: - Endpoint Security: Secure the endpoint, stop the breach - Identify Protection: Identity is the front line, defend it - Next-Gen SIEM: The future of SIEM, today - Data Protection: Real-time data protection from endpoint to cloud - Exposure Management: Understand risk to stop breaches - Charlotte AI: Powering the next evolution of the SOC

Average Rating: 4.7/5.0

Total Reviews: 544

How Do G2 Users Rate CrowdStrike Falcon Endpoint Protection Platform?

  • Threat Intelligence: 9.5/10 (Category avg: 8.9/10)
  • Quality of Support: 9.0/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.3/10 (Category avg: 8.5/10)
  • Incident Logs: 8.9/10 (Category avg: 8.8/10)

Who Is the Company Behind CrowdStrike Falcon Endpoint Protection Platform?

  • Seller: CrowdStrike
  • Company Website:
  • Year Founded: 2011
  • HQ Location: Sunnyvale, CA
  • Twitter: @CrowdStrike
    110,809 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    21,058 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Analyst, Security Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 46% Large, 40% Medium

What Do G2 Reviewers Say About CrowdStrike Falcon Endpoint Protection Platform?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the lightweight performance and powerful threat detection of CrowdStrike Falcon, enhancing security without slowing down systems.
  • Users commend the effective threat detection capabilities of CrowdStrike Falcon, ensuring robust security without system slowdowns.
  • Users appreciate the ease of use of CrowdStrike Falcon, benefiting from its lightweight impact and efficient incident management.
  • Users appreciate the advanced real-time threat protection of CrowdStrike Falcon, ensuring efficient security without system performance issues.
  • Users praise the exceptional threat detection of CrowdStrike Falcon, noting its effectiveness against both known and unknown threats.
Cons
  • Users find the cost prohibitive for smaller organizations, especially with additional modules increasing overall expenses.
  • Users find the complexity of the user interface and additional costs challenging, complicating their overall experience.
  • Users face a steep learning curve with CrowdStrike’s query language, making transitions from other platforms challenging.
  • Users find the limited features challenging, especially concerning cost and technical accessibility for smaller businesses.
  • Users find that pricing can be a barrier for smaller organizations, complicating access to advanced features.

What Are Recent G2 Reviews of CrowdStrike Falcon Endpoint Protection Platform?

What Are G2 Users Discussing About CrowdStrike Falcon Endpoint Protection Platform?

Tines Stories

Tines is the intelligent workflow platform trusted by the world's most advanced organizations. Companies like Coinbase, Databricks, Mars, Reddit, and SAP use Tines to power their most important workflows. With Tines, they’ve built a secure, flexible foundation to operationalize AI agents and intelligent workflows, unlocking productivity, moving faster, and future-proofing how work gets done.

Average Rating: 4.7/5.0

Total Reviews: 424

How Do G2 Users Rate Tines Stories?

  • Threat Intelligence: 8.8/10 (Category avg: 8.9/10)
  • Quality of Support: 9.5/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.7/10 (Category avg: 8.5/10)
  • Incident Logs: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind Tines Stories?

  • Seller: Tines
  • Company Website:
  • Year Founded: 2018
  • HQ Location: Dublin, IE
  • LinkedIn® Page: www.linkedin.com
    619 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Security Engineer, Software Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 38% Medium, 35% Large

What Do G2 Reviewers Say About Tines Stories?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Tines, enabling seamless automation without any coding knowledge.
  • Users highlight the flexibility and ease of automation with Tines, making integration and workflow creation seamless.
  • Users commend Tines for its exceptional customer support, appreciating the team's responsiveness and proactive assistance.
  • Users highlight Tines for its ease of use and rapid implementation, significantly boosting team efficiency and automation capabilities.
  • Users value Tines for its time-saving automation capabilities, allowing teams to focus on more strategic activities efficiently.
Cons
  • Users note a steep learning curve with Tines, especially for newcomers to automation and orchestration tools.
  • Users find Tines lacking in missing features that can hinder initial onboarding and expectations for functionality.
  • Users note a lack of features in Tines, pointing out missing options and inconsistencies in functionality.
  • Users find the complexity of advanced features in Tines overwhelming, especially for teams lacking a clear strategy.
  • Users find Tines has a difficult learning curve, particularly for newcomers to automation and orchestration tools.

What Are Recent G2 Reviews of Tines Stories?

What Are G2 Users Discussing About Tines Stories?

Torq AI SOC Platform

Torq is the AI SOC platform that combines agentic insights and automation so that enterprises can triage, investigate, and respond to actual risks, faster. Torq streamlines every step from alert through resolution. The platform analyzes your risk context to identify your biggest threats. Working alongside your SecOps staff, the Torq platform integrates with your security stack to facilitate containment and remediation workflows.

Average Rating: 4.8/5.0

Total Reviews: 151

How Do G2 Users Rate Torq AI SOC Platform?

  • Threat Intelligence: 8.9/10 (Category avg: 8.9/10)
  • Quality of Support: 9.6/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.9/10 (Category avg: 8.5/10)
  • Incident Logs: 8.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Torq AI SOC Platform?

  • Seller: torq
  • Company Website:
  • Year Founded: 2020
  • HQ Location: New York, US
  • Twitter: @torq_io
    1,944 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    470 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 49% Medium, 30% Small

What Do G2 Reviewers Say About Torq AI SOC Platform?

AI-generated summary from verified user reviews

Pros
  • Users praise the ease of use of Torq AI SOC Platform, making it accessible for all skill levels.
  • Users value the efficiency of automated security workflows in Torq, enhancing both speed and effectiveness in threat management.
  • Users value the automation capabilities of Torq AI SOC Platform, enhancing efficiency and streamlining security workflows effectively.
  • Users appreciate the no-code automation capabilities of Torq, streamlining workflows and enhancing overall operational efficiency.
  • Users value the real-time threat detection of Torq AI SOC Platform, enhancing efficiency in responding to security incidents.
Cons
  • Users face a difficult learning curve with Torq AI SOC Platform, requiring significant training and support for effective use.
  • Users face a significant learning curve with Torq AI SOC Platform, requiring time and proper training for effective use.
  • Users note the missing features in Torq AI SOC Platform, especially regarding playbooks and incident management capabilities.
  • Users note that improvement is needed in grouping findings, vendor integration, and overall flexibility for better experience.
  • Users face poor interface design in Torq, including unresponsive buttons and a challenging debugging process.

What Are Recent G2 Reviews of Torq AI SOC Platform?

Palo Alto Cortex XSIAM

Product Description: Palo Alto Networks' Cortex XSIAM is an AI-driven security operations platform designed to transform traditional Security Operations Centers by integrating and automating key functions such as data centralization, threat detection, and incident response. By leveraging machine learning and automation, it enables organizations to detect and respond to threats more efficiently, reducing manual workloads and improving overall security posture. Key Features and Functionality: - Data Centralization: Aggregates data from various sources into a unified platform, providing comprehensive visibility across the enterprise. - AI-Powered Threat Detection: Utilizes machine learning algorithms to identify anomalies and potential threats in real-time. - Automated Incident Response: Streamlines response processes through automation, enabling rapid mitigation of security incidents. - Integrated SOC Capabilities: Combines functions such as Extended Detection and Response , Security Orchestration, Automation, and Response , Attack Surface Management , and Security Information and Event Management into a cohesive platform, eliminating the need for multiple disparate tools. - Scalability: Designed to handle large volumes of data and adapt to the evolving needs of modern enterprises. Primary Value and Problem Solved: Cortex XSIAM addresses the challenges of disjointed data, weak threat defense, and heavy reliance on manual work in traditional SOCs. By centralizing data and automating security operations, it simplifies processes, enhances threat detection accuracy, and accelerates incident response times. This transformation enables organizations to proactively outpace threats, reduce operational costs, and achieve a more robust security posture.

Average Rating: 4.5/5.0

Total Reviews: 96

How Do G2 Users Rate Palo Alto Cortex XSIAM?

  • Threat Intelligence: 8.9/10 (Category avg: 8.9/10)
  • Quality of Support: 8.5/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.5/10 (Category avg: 8.5/10)
  • Incident Logs: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Palo Alto Cortex XSIAM?

  • Seller: Palo Alto Networks
  • Company Website:
  • Year Founded: 2005
  • HQ Location: Santa Clara, CA
  • Twitter: @PaloAltoNtwks
    128,951 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    23,492 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 40% Large, 36% Medium

What Do G2 Reviewers Say About Palo Alto Cortex XSIAM?

AI-generated summary from verified user reviews

Pros
  • Users value the best-in-class log management of Palo Alto Cortex XSIAM, benefiting from its effective alerting and integration features.
  • Users find the user-friendly dashboard of Palo Alto Cortex XSIAM essential for monitoring and understanding alerts effectively.
  • Users value the real-time monitoring capabilities of Palo Alto Cortex XSIAM, enhancing threat detection and response efficiency.
  • Users value the simple and user-friendly interface of Palo Alto Cortex XSIAM, making monitoring effortless.
  • Users value the good dashboard creation tools in Palo Alto Cortex XSIAM, enhancing ease of use and implementation.
Cons
  • Users note that Palo Alto Cortex XSIAM requires significant resources, impacting implementation time and increasing infrastructure costs.
  • Users find the complexity of implementation for Palo Alto Cortex XSIAM to be time-consuming and resource-intensive.
  • Users find the cost of Palo Alto Cortex XSIAM to be high, especially for smaller businesses.
  • Users face dashboard issues with XSIAM, finding it difficult to monitor assets and navigate the interface.
  • Users face difficult setup issues with Palo Alto Cortex XSIAM, requiring expertise and extensive time for initial implementation.

What Are Recent G2 Reviews of Palo Alto Cortex XSIAM?

What Are G2 Users Discussing About Palo Alto Cortex XSIAM?

Cynet

Cynet is the unified, AI-powered cybersecurity platform that delivers robust and comprehensive protection for security teams while maximizing operational efficiency for managed service providers (MSPs). This platform consolidates a wide array of security capabilities into a single, user-friendly interface, ensuring that organizations can effectively safeguard their digital assets without the complexity often associated with multi-solution environments. Cynet’s platform simplifies security management by integrating various functionalities, such as endpoint protection, threat detection, and incident response, into one cohesive system. This integration not only streamlines operations but also allows organizations to allocate their resources more effectively, ultimately enhancing their overall security posture. One of the standout features of Cynet’s platform is its remarkable performance in the MITRE ATT&CK Evaluations. Cynet delivered 100% visibility and 100% analytic coverage without requiring any configuration changes three years in a row. This capability ensures that organizations can monitor their environments comprehensively and respond to threats with precision. The platform’s built-in analytics and reporting tools provide actionable insights, enabling users to make informed decisions about their cybersecurity strategies. Additionally, Cynet offers 24/7 expert support, which is crucial for organizations that may not have in-house cybersecurity expertise. This round-the-clock assistance ensures that users can quickly address any security incidents or concerns, minimizing potential downtime and damage. The combination of advanced technology and dedicated support positions Cynet as a valuable partner for SMEs and service providers looking to enhance their cybersecurity measures. In summary, Cynet’s unified, AI-powered cybersecurity platform stands out in the crowded cybersecurity market by offering a unified solution tailored to the needs of MSPs. Its comprehensive features, exceptional performance in industry evaluations, and continuous expert support make it a compelling choice for organizations seeking to bolster their cybersecurity defenses while maintaining operational efficiency.

Average Rating: 4.7/5.0

Total Reviews: 218

How Do G2 Users Rate Cynet?

  • Threat Intelligence: 9.2/10 (Category avg: 8.9/10)
  • Quality of Support: 9.3/10 (Category avg: 8.8/10)
  • Incident Case Management: 9.0/10 (Category avg: 8.5/10)
  • Incident Logs: 9.2/10 (Category avg: 8.8/10)

Who Is the Company Behind Cynet?

  • Seller: Cynet
  • Company Website:
  • Year Founded: 2014
  • HQ Location: Boston, MA
  • LinkedIn® Page: www.linkedin.com
    335 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: SOC Analyst, Technical Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 58% Medium, 30% Small

What Do G2 Reviewers Say About Cynet?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Cynet, appreciating its straightforward yet comprehensive functionalities for effective protection.
  • Users value the unified platform of Cynet, which offers effective security through streamlined endpoint protection and detection.
  • Users praise Cynet for its effective threat detection and seamless monitoring, enhancing overall cybersecurity effortlessly.
  • Users commend Cynet for its exceptional customer support, ensuring a smooth and efficient deployment experience.
  • Users praise Cynet for its flawless threat monitoring and detection, enhancing overall cybersecurity effectiveness effortlessly.
Cons
  • Users find limited customization options in reporting and dashboards, affecting their ability to present necessary data.
  • Users note a lack of customization in reports, wishing for more options to tailor data presentation.
  • Users find the reporting features lacking, with requests for better customization and visualization tools.
  • Users find feature limitations in Cynet, with a desire for more customization options and broader integrations.
  • Users note limited features, such as basic reporting and few third-party integrations, impacting customization and deeper controls.

What Are Recent G2 Reviews of Cynet?

What Are G2 Users Discussing About Cynet?

KnowBe4 PhishER/PhishER Plus

KnowBe4 PhishER Plus delivers automated incident response to eliminate SOC noise and remediate malicious emails across your organization simultaneously. It leverages AI to categorize reported messages across email and Microsoft Teams, automatically responding to reporters, flagging high-risk messages, and removing threats across all mailboxes. SOC teams can even flip malicious messages into training simulations to see who would have fallen victim. Customers report saving upwards of 99% of triage time, highly praising the platform's intuitive, user-friendly interface that transforms overwhelming manual workflows into fast, consistent actions. This layer of defense reviews threats slipping past other security layers, offering a single pane of glass view with leading third-party integrations like CrowdStrike, Webroot, and VirusTotal. PhishER Plus turns manual email triaging into a proactive, automated security posture.

Average Rating: 4.5/5.0

Total Reviews: 570

How Do G2 Users Rate KnowBe4 PhishER/PhishER Plus?

  • Threat Intelligence: 8.5/10 (Category avg: 8.9/10)
  • Quality of Support: 9.2/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.9/10 (Category avg: 8.5/10)
  • Incident Logs: 8.4/10 (Category avg: 8.8/10)

Who Is the Company Behind KnowBe4 PhishER/PhishER Plus?

  • Seller: KnowBe4, Inc.
  • Company Website:
  • Year Founded: 2010
  • HQ Location: Clearwater, FL
  • Twitter: @KnowBe4
    16,161 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2,642 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: IT Manager, Director of IT
  • Top Industries: Financial Services, Primary/Secondary Education
  • Company Size: 75% Medium, 13% Large

What Do G2 Reviewers Say About KnowBe4 PhishER/PhishER Plus?

AI-generated summary from verified user reviews

Pros
  • Users value the effective phishing tests and automation features of KnowBe4 PhishER, enhancing their security posture.
  • Users appreciate the email threat scoring feature of KnowBe4 PhishER, enabling proactive responses to potential threats.
  • Users value the automation capabilities of KnowBe4 PhishER, enhancing efficiency in identifying and managing phishing threats.
  • Users find KnowBe4 PhishER/PhishER Plus remarkably easy to use, enhancing efficiency in triaging and reporting spam emails.
  • Users appreciate the streamlined threat detection of KnowBe4 PhishER, making phishing email management effortless and efficient.
Cons
  • Users report issues with clean emails landing in the Junk Email folder, leading to troubleshooting difficulties and uncertainty.
  • Users experience frequent false positives, complicating automation and necessitating time-consuming manual reviews for accuracy.
  • Users experience ineffective email security with PhishER, as it fails to correctly filter phishing emails into the inbox.
  • Users find the learning curve intimidating for setup, requiring additional assistance for effective use of PhishER/PhishER Plus.
  • Users find the inefficient automation of PhishER frustrating, as it often misses campaigns and requires manual intervention.

What Are Recent G2 Reviews of KnowBe4 PhishER/PhishER Plus?

What Are G2 Users Discussing About KnowBe4 PhishER/PhishER Plus?

SentinelOne Singularity Endpoint

SentinelOne® Singularity™ Endpoint is an autonomous endpoint security platform that stops threats in real-time. It unifies endpoint protection (EPP), endpoint detection and response (EDR), and autonomous remediation to stop ransomware, zero-day exploits, supply chain attacks, and fileless malware. Singularity Endpoint protects workstations, mobile devices, servers, and cloud workloads across SaaS, on-premises, hybrid, and air-gapped environments. Behavioral and static AI detection models stop known and unknown threats by identifying how threats behave, not just what they look like. SentinelOne catches what signatures miss, without waiting on updates. Storyline® automatically correlates telemetry into one visual attack story, and patented one-click rollback restores systems to a trusted state in seconds. The result is stronger protection with fewer incidents and less operational overhead: lower dwell time, fewer false positives, and faster response. With Purple AI™, teams accelerate triage, threat hunting, and investigation. From alert to verdict without manual investigation. Purple AI's Agentic Investigation runs the analysis, surfaces the evidence, and tells your team exactly what to do next. The same SentinelOne agent that protects endpoints also defends every identity behind them. Detect credential abuse, shrink your attack surface, and contain identity threats from one console. Seamless integration of endpoint, identity, cloud, and third-party telemetry eliminates blind spots. Built AI-native from day one, Singularity Endpoint delivers best-in-industry coverage across Windows, macOS, Linux, and mobile operating systems, including legacy OSes. Trusted by more than 11,500 customers, SentinelOne is a six-time Gartner® Magic Quadrant™ Leader for Endpoint Protection.

Average Rating: 4.7/5.0

Total Reviews: 205

How Do G2 Users Rate SentinelOne Singularity Endpoint?

  • Threat Intelligence: 10.0/10 (Category avg: 8.9/10)
  • Quality of Support: 8.9/10 (Category avg: 8.8/10)
  • Incident Case Management: 10.0/10 (Category avg: 8.5/10)
  • Incident Logs: 10.0/10 (Category avg: 8.8/10)

Who Is the Company Behind SentinelOne Singularity Endpoint?

  • Seller: SentinelOne
  • Company Website:
  • Year Founded: 2013
  • HQ Location: Mountain View, CA
  • Twitter: @SentinelOne
    57,863 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6,571 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 45% Medium, 36% Large

What Do G2 Reviewers Say About SentinelOne Singularity Endpoint?

AI-generated summary from verified user reviews

Pros
  • Users value the tool efficiency of SentinelOne Singularity Endpoint, appreciating its user-friendly interface and effective threat detection.
  • Users find the ease of integration with Nable RMM and setup straightforward for daily operations.
  • Users praise the exceptional malware protection of SentinelOne, effectively stopping threats before they can cause harm.
  • Users find SentinelOne Singularity Endpoint to be a highly useful tool for incident notification and investigation.
  • Users appreciate the quick alerts and feature-rich capabilities of SentinelOne, enhancing security management and support.
Cons
  • Users face update issues with SentinelOne Singularity, leading to login problems and cumbersome agent management.
  • Users find the difficult learning curve of SentinelOne Singularity Endpoint challenging, especially for beginners navigating its features.
  • Users find the frequent updates challenging, as rapid changes lead to login issues and a steep learning curve.
  • Users report challenges with agent removal issues impacting application functionality and requiring improvement in uninstallation processes.
  • Users report ineffective alerts that hinder troubleshooting and prevent them from addressing application issues effectively.

What Are Recent G2 Reviews of SentinelOne Singularity Endpoint?

What Are G2 Users Discussing About SentinelOne Singularity Endpoint?

Wazuh

Wazuh is a free and open source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh, with over 30 million downloads per year, has one of the largest open-source security communities in the world. Wazuh helps organizations of all sizes protect their data assets against security threats. Learn more about the project at wazuh.com

Average Rating: 4.5/5.0

Total Reviews: 70

How Do G2 Users Rate Wazuh?

  • Threat Intelligence: 8.7/10 (Category avg: 8.9/10)
  • Quality of Support: 8.4/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.9/10 (Category avg: 8.5/10)
  • Incident Logs: 9.1/10 (Category avg: 8.8/10)

Who Is the Company Behind Wazuh?

  • Seller: Wazuh Inc.
  • Year Founded: 2015
  • HQ Location: Campbell, US
  • Twitter: @wazuh
    8,026 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    270 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: SOC Analyst
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 47% Small, 40% Medium

What Do G2 Reviewers Say About Wazuh?

AI-generated summary from verified user reviews

Pros
  • Users value the user-friendly design of Wazuh, making it simple to implement and manage security tasks effectively.
  • Users value Wazuh for its affordability, benefiting from enterprise-level security without high licensing costs.
  • Users value the real-time threat detection and control offered by Wazuh for robust cybersecurity across their infrastructure.
  • Users value the easy management of Wazuh, simplifying their experience and streamlining operations effectively.
  • Users find the easy setup of Wazuh beneficial, enabling quick deployment and configuration for endpoint monitoring.
Cons
  • Users find the complex interface challenging, with a steep learning curve and time-consuming configurations for new users.
  • Users find Wazuh to have a steep learning curve and convoluted setup, making it challenging for new users.
  • Users face significant challenges with complex implementation of Wazuh, making setup and management difficult.
  • Users face a difficult learning curve with Wazuh, particularly during setup and configuration, hindering initial use.
  • Users face a difficult setup with Wazuh, often struggling with the steep learning curve and time-consuming configurations.

What Are Recent G2 Reviews of Wazuh?

What Are G2 Users Discussing About Wazuh?

IBM QRadar SIEM

Outsmart threats with an end-to-end award-winning security suite; proven to prevent, endure and recover from both known & unknown IT hazards faced by SoCs in the modern-day.

Average Rating: 4.4/5.0

Total Reviews: 284

How Do G2 Users Rate IBM QRadar SIEM?

  • Threat Intelligence: 8.4/10 (Category avg: 8.9/10)
  • Quality of Support: 8.3/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.3/10 (Category avg: 8.5/10)
  • Incident Logs: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind IBM QRadar SIEM?

  • Seller: IBM
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®
  • Ownership: SWX:IBM

Who Uses This Product?

  • Who Uses This: SOC Analyst, Security Engineer
  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 53% Large, 29% Medium

What Do G2 Reviewers Say About IBM QRadar SIEM?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of IBM QRadar SIEM, facilitating effective threat management and investigation.
  • Users appreciate the flexible integration capabilities of IBM QRadar SIEM, enhancing log management across diverse sources.
  • Users value the advanced threat detection and centralized log management features of IBM QRadar SIEM for enhanced security.
  • Users appreciate the easy integrations of IBM QRadar SIEM, enhancing its functionality with various platforms seamlessly.
  • Users appreciate the user-friendly interface of IBM QRadar SIEM, making it accessible for both tech and non-tech users.
Cons
  • Users find the UX improvements lacking, struggling with limited features and an unfriendly interface in QRadar SIEM.
  • Users find IBM QRadar SIEM expensive, particularly small and mid-sized companies struggling with the overall cost.
  • Users find the high cost of IBM QRadar SIEM challenging, particularly for smaller organizations needing comprehensive support.
  • Users face dashboard issues with IBM QRadar SIEM, lacking customization, usability, and integration for optimal performance.
  • Users find the time-consuming nature of QRadar SIEM frustrating, especially with complicated queries and log fetching delays.

What Are Recent G2 Reviews of IBM QRadar SIEM?

Microsoft Sentinel

Microsoft Sentinel lets you see and stop threats before they cause harm, with SIEM reinvented for a modern world. Microsoft Sentinel is your birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make your threat detection and response smarter and faster with artificial intelligence (AI). Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. With Microsoft Sentinel, you can: - Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds - Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft - Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft -Respond to incidents rapidly with built-in orchestration and automation of common tasks

Average Rating: 4.4/5.0

Total Reviews: 275

How Do G2 Users Rate Microsoft Sentinel?

  • Quality of Support: 8.5/10 (Category avg: 8.8/10)

Who Is the Company Behind Microsoft Sentinel?

  • Seller: Microsoft
  • Year Founded: 1975
  • HQ Location: Redmond, Washington
  • Twitter: @microsoft
    13,091,739 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    232,750 employees on LinkedIn®
  • Ownership: MSFT

Who Uses This Product?

  • Who Uses This: Security Analyst, Senior Software Engineer
  • Top Industries: Information Technology and Services, Computer & Network Security
  • Company Size: 42% Large, 31% Medium

What Do G2 Reviewers Say About Microsoft Sentinel?

AI-generated summary from verified user reviews

Pros
  • Users value the advanced threat detection of Microsoft Sentinel, enhancing security and proactive threat management.
  • Users value the easy integrations of Microsoft Sentinel, facilitating quick setup and streamlined security processes.
  • Users value the seamless integration of Microsoft Sentinel with various third-party and Microsoft products, enhancing functionality and management.
  • Users commend the ease of use of Microsoft Sentinel, facilitating quick integration and a user-friendly experience.
Cons
  • Users express concern over the high costs of Microsoft Sentinel, especially as data ingestion increases.
  • Users face integration issues with Microsoft Sentinel, especially when connecting to legacy systems and third-party tools.
  • Users find the complexity of Microsoft Sentinel challenging, requiring extensive training and effort for effective use.

What Are Recent G2 Reviews of Microsoft Sentinel?

What Are G2 Users Discussing About Microsoft Sentinel?

IBM Concert platform

IBM Concert® is an agentic IT Ops platform that creates an adaptable, unified operational layer across your environment. It connects signals, generates shared context, and coordinates action across teams and tools, so your entire system operates as one. With cross-domain intelligence, Concert helps you reduce risk, maintain business continuity, improve performance, and optimize cost across the stack. Powered by agentic AI, it surfaces what matters, prioritizes business impact, and orchestrates action through governed workflows. 

Average Rating: 4.2/5.0

Total Reviews: 27

How Do G2 Users Rate IBM Concert platform?

  • Quality of Support: 7.3/10 (Category avg: 8.8/10)

Who Is the Company Behind IBM Concert platform?

  • Seller: IBM
  • Company Website:
  • Year Founded: 1911
  • HQ Location: Armonk, New York, United States
  • Twitter: @IBMSecurity
    74,660 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    344,328 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 41% Small, 37% Medium

What Do G2 Reviewers Say About IBM Concert platform?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of IBM Concert, which simplifies project management and enhances team communication effectively.
  • Users value the end-to-end visibility and actionable insights of IBM Concert, enhancing focus and collaboration in their workflows.
  • Users value the automation capabilities of IBM Concert, enhancing efficiency and collaboration while minimizing manual efforts.
  • Users find the easy setup of IBM Concert smooth, enhancing productivity by integrating multiple tools into one platform.
  • Users value IBM Concert for its effective problem-solving capabilities, offering clear insights and speeding up incident resolution.
Cons
  • Users find the learning difficulty of IBM Concert challenging, often requiring time and better onboarding support.
  • Users find the initial setup complex, with a steep learning curve that challenges new users to get acquainted.
  • Users feel the learning curve is steep, making it challenging to grasp all features of IBM Concert quickly.
  • Users face integration issues with IBM Concert, noting the need for smoother connections and improved onboarding support.
  • Users express a need for limited customization options in IBM Concert, which hinder adaptability for diverse team requirements.

What Are Recent G2 Reviews of IBM Concert platform?

Sumo Logic

Sumo Logic, Inc. unifies and analyzes enterprise data, translating it into actionable insights through one AI-powered cloud-native log analytics platform. This single source of truth enables Dev, Sec and Ops teams to simplify complexity, collaborate efficiently and accelerate data-driven decisions that drive business value. Customers around the world rely on the Sumo Logic SaaS Log Analytics Platform for trusted insights to ensure application reliability, secure and protect against modern security threats, and gain insights into their cloud infrastructures. For more information, visit: SUMOLOGIC.COM

Average Rating: 4.3/5.0

Total Reviews: 405

How Do G2 Users Rate Sumo Logic?

  • Threat Intelligence: 7.7/10 (Category avg: 8.9/10)
  • Quality of Support: 8.5/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.1/10 (Category avg: 8.5/10)
  • Incident Logs: 8.8/10 (Category avg: 8.8/10)

Who Is the Company Behind Sumo Logic?

  • Seller: Sumo Logic
  • Company Website:
  • Year Founded: 2010
  • HQ Location: Redwood City, CA
  • Twitter: @SumoLogic
    6,542 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    824 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 48% Medium, 38% Large

What Do G2 Reviewers Say About Sumo Logic?

AI-generated summary from verified user reviews

Pros
  • Users highlight the ease of use in Sumo Logic, citing its simple query language and intuitive configurations.
  • Users value the ease of searching and configuring logs with Sumo Logic, enhancing their monitoring and tracing efficiency.
  • Users appreciate the Comprehensive Continuous Intelligence feature of Sumo Logic for transforming data into actionable insights quickly.
  • Users value the powerful visual insights and efficient log management capabilities of Sumo Logic for fast resolution.
  • Users value the real-time monitoring capabilities of Sumo Logic, enjoying swift insights and effective data management.
Cons
  • Users find Sumo Logic expensive, prompting concerns about whether its value justifies the high pricing.
  • Users find the difficult learning curve of Sumo Logic challenging, requiring significant time to become proficient.
  • Users face a steep learning curve with Sumo Logic, requiring significant time to master its features and query language.
  • Users face a steep learning curve with Sumo Logic, requiring significant time to master complex features and queries.
  • Users experience slow performance with Sumo Logic, facing delays in alerting and a cumbersome user interface.

What Are Recent G2 Reviews of Sumo Logic?

What Are G2 Users Discussing About Sumo Logic?

SpinOne

SpinOne is an AI-powered SaaS data protection platform that combines automated backup and recovery, Data Leak and Loss Prevention (DLP), SaaS Security Posture Management (SSPM), ransomware protection, and continuous security monitoring to protect business-critical data across Google Workspace, Microsoft 365, Salesforce, and Slack. Recognized by Gartner in the Market Guide for SaaS Security Posture Management, SpinOne helps organizations secure, protect, recover, and govern SaaS data across their most critical cloud applications. Unlike traditional backup solutions or standalone security tools, SpinOne unifies SaaS backup, data recovery, Data Leak and Loss Prevention (DLP), SaaS Security Posture Management (SSPM), ransomware protection, and automated security controls in a single platform. Organizations use SpinOne to prevent data loss, reduce cyber risk, strengthen compliance, and improve business continuity. SpinOne provides automated Google Workspace backup and recovery for Gmail, Google Drive, Shared Drives, Calendar, Contacts, and Google Sites. IT teams can restore individual files, emails, folders, users, or complete accounts with point-in-time recovery to minimize downtime caused by accidental deletion, ransomware, insider threats, malicious applications, or operational errors. SpinOne also provides Microsoft 365 backup and recovery for Exchange Online, OneDrive, SharePoint, and Microsoft Teams. Across SaaS applications, SpinOne helps organizations maintain secure, recoverable, and compliant business data. Beyond backup and recovery, SpinOne protects SaaS environments with AI-powered Data Leak and Loss Prevention (DLP), helping organizations identify sensitive information, prevent unauthorized data exposure, reduce data leakage risks, and enforce security policies. SpinOne SaaS Security Posture Management (SSPM) continuously monitors SaaS environments, identifies security risks, detects misconfigurations, and helps automate remediation. Key capabilities include: Google Workspace backup and recovery Microsoft 365 backup and recovery SaaS backup and data protection Data Leak Prevention (DLP) Data Loss Prevention (DLP) SaaS Security Posture Management (SSPM) Ransomware detection and recovery Point-in-time recovery and granular restore Continuous SaaS security monitoring Sensitive data protection Compliance and audit readiness Business continuity and disaster recovery SpinOne has been recognized by Cyber Defense Magazine through multiple Global InfoSec Awards, including recognition for Secure SaaS Backup, Ransomware Protection for SaaS Data, SaaS/Cloud Security, Browser Security, and Data Security Posture Management categories. SpinOne helps organizations protect SaaS data throughout its lifecycle—from preventing data leaks and security risks to backing up critical information, detecting ransomware, and rapidly recovering after cyber incidents. Organizations choose SpinOne as a unified SaaS data protection platform to secure, back up, recover, and govern critical data across Google Workspace, Microsoft 365, Salesforce, and Slack.

Average Rating: 4.8/5.0

Total Reviews: 129

G2 Deal: Get $ 500 off SpinOne with this exclusive G2 deal!

SpinOne is an all-in-one, SaaS security platform that protects SaaS data for mission-critical SaaS applications. Start a 15-day free trial of SpinOne. When you're ready to purchase, add the promo code "SPINLOVER" to claim $ 500 off your first year of a main subscription purchase of SpinOne.

Price: $500 Off

View this exclusive G2 deal

How Do G2 Users Rate SpinOne?

  • Threat Intelligence: 9.2/10 (Category avg: 8.9/10)
  • Quality of Support: 9.6/10 (Category avg: 8.8/10)
  • Incident Case Management: 9.3/10 (Category avg: 8.5/10)
  • Incident Logs: 9.4/10 (Category avg: 8.8/10)

Who Is the Company Behind SpinOne?

  • Seller: SpinAI
  • Company Website:
  • Year Founded: 2017
  • HQ Location: Palo Alto, California
  • Twitter: @spintechinc
    766 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    91 employees on LinkedIn®

Who Uses This Product?

  • Who Uses This: CEO, IT Director
  • Top Industries: Marketing and Advertising, Non-Profit Organization Management
  • Company Size: 52% Medium, 39% Small

What Do G2 Reviewers Say About SpinOne?

AI-generated summary from verified user reviews

Pros
  • Users highlight the exceptional customer support from SpinOne, providing tailored solutions and easy integration for peace of mind.
  • Users appreciate the ease of use of SpinOne, highlighting seamless integration and straightforward setup for peace of mind.
  • Users value the ease of use and reliable backups of SpinOne, ensuring peace of mind with data protection.
  • Users value the reliability of SpinOne for secure and intuitive backup of their Google Workspace data.
  • Users value SpinOne's reliable backup features that ensure data security and easy management, enhancing peace of mind.
Cons
  • Users report backup issues with limited management features, large backup delays, and a frustrating interface performance.
  • Users experience poor interface design in SpinOne, which complicates navigation and affects task efficiency.
  • Users find the cost prohibitive for large organizations, limiting accessibility and backup options for smaller entities.
  • Users find the pricing issues of SpinOne challenging, particularly for small organizations and archived users.
  • Users face unclear guidance due to limited resources and a complex manual process, complicating their experience with SpinOne.

What Are Recent G2 Reviews of SpinOne?

What Are G2 Users Discussing About SpinOne?

Splunk Enterprise Security

Splunk Enterprise Security (ES) is a data-centric, modern security information and event management (SIEM) solution that delivers data-driven insights for full breadth visibility into your security posture so you can protect your business and mitigate risk at scale. With unparalleled search and reporting, advanced analytics, integrated intelligence, and prepackaged security content, Splunk ES accelerates threat detection and investigation, letting you determine the scope of high-priority threats to your environment so you can quickly take action. Built on an open and scalable data platform, you can stay agile in the face of evolving threats and business needs. Our extensive ecosystem of Splunk, partner, and community-built integrations as well as flexible deployment options ensure your technology investments are working in tandem with Splunk ES whilst meeting you wherever you are on your cloud, multi-cloud, or hybrid journey.

Average Rating: 4.3/5.0

Total Reviews: 224

How Do G2 Users Rate Splunk Enterprise Security?

  • Threat Intelligence: 9.0/10 (Category avg: 8.9/10)
  • Quality of Support: 8.6/10 (Category avg: 8.8/10)
  • Incident Case Management: 7.5/10 (Category avg: 8.5/10)
  • Incident Logs: 8.0/10 (Category avg: 8.8/10)

Who Is the Company Behind Splunk Enterprise Security?

  • Seller: Cisco
  • Year Founded: 1984
  • HQ Location: San Jose, CA
  • Twitter: @Cisco
    720,366 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    95,294 employees on LinkedIn®
  • Ownership: NASDAQ:CSCO

Who Uses This Product?

  • Who Uses This: Software Engineer, Senior Software Engineer
  • Top Industries: Information Technology and Services, Computer Software
  • Company Size: 59% Large, 30% Medium

What Do G2 Reviewers Say About Splunk Enterprise Security?

AI-generated summary from verified user reviews

Pros
  • Users value the ease of use of Splunk Enterprise Security, enhancing their monitoring and log management experience.
  • Users appreciate the easy integrations of Splunk Enterprise Security, enabling seamless connection with various platforms and systems.
  • Users highlight the impressive threat detection capabilities of Splunk Enterprise Security, enhancing security focus and reducing false alarms.
  • Users value the effective features of Splunk Enterprise Security, enhancing security analysis with comprehensive logs and insights.
  • Users appreciate the user-friendly interface of Splunk Enterprise Security, enabling efficient monitoring and attractive dashboards.
Cons
  • Users find the high costs associated with data ingestion to be a significant drawback of Splunk Enterprise Security.
  • Users find the initial implementation complex, needing expert resources and time to onboard Splunk Enterprise Security effectively.
  • Users find the complex implementation of Splunk Enterprise Security challenging, requiring extensive expertise and resources.
  • Users find the complex setup of Splunk Enterprise Security time-consuming and challenging, impacting initial deployment effectiveness.
  • Users find the difficult learning curve of Splunk Enterprise Security challenging, especially for those new to data analysis.

What Are Recent G2 Reviews of Splunk Enterprise Security?

What Are G2 Users Discussing About Splunk Enterprise Security?

CYREBRO

CYREBRO is an AI-native Managed Detection and Response solution, providing the core foundation and capabilities of a state-level Security Operations Center delivered through its cloud-based, interactive SOC Platform. CYREBRO rapidly detects, analyzes, investigates and responds to cyber threats, for businesses of all sizes.

Average Rating: 4.3/5.0

Total Reviews: 128

How Do G2 Users Rate CYREBRO?

  • Threat Intelligence: 8.6/10 (Category avg: 8.9/10)
  • Quality of Support: 8.3/10 (Category avg: 8.8/10)
  • Incident Case Management: 8.0/10 (Category avg: 8.5/10)
  • Incident Logs: 8.6/10 (Category avg: 8.8/10)

Who Is the Company Behind CYREBRO?

  • Seller: CYREBRO
  • Year Founded: 2013
  • HQ Location: Tel Aviv, IL
  • Twitter: @CYREBRO_IO
    307 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    81 employees on LinkedIn®

Who Uses This Product?

  • Top Industries: Computer & Network Security, Information Technology and Services
  • Company Size: 64% Medium, 25% Small

What Do G2 Reviewers Say About CYREBRO?

AI-generated summary from verified user reviews

Pros
  • Users appreciate the ease of use of CYREBRO, thanks to its intuitive UI and quick access to investigations.
  • Users value the responsive and knowledgeable customer support of CYREBRO, enhancing their overall experience and satisfaction.
  • Users value the dashboard usability of CYREBRO, benefiting from easy management and seamless incident response.
  • Users value the real-time alerts and actionable insights from CYREBRO, enhancing their security response and peace of mind.
  • Users value the real-time alerts from CYREBRO that enhance response time and simplify incident management effectively.
Cons
  • Users report experiencing update issues with alert management, leading to overwhelmed users and hindered onboarding processes.
  • Users face communication issues with Cyrebro support, experiencing slow response times and vague information that complicates problem resolution.
  • Users report poor customer support with slow response times and limited availability, impacting their overall experience.
  • Users often find ineffective alerts from CYREBRO, struggling with overwhelming volume and vague details requiring further support.
  • Users report an inefficient alert system, with overwhelming notifications and redundant alerts complicating their experience.

What Are Recent G2 Reviews of CYREBRO?

What Are G2 Users Discussing About CYREBRO?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated